Courseiva

AI0-001 AI Security, Ethics and Governance Practice Question

Which TWO of the following are common threats to AI model security?

⚠ Common exam trap

The AI0-001 exam often tests the distinction between traditional IT security threats (like SQL injection or DDoS) and AI-specific threats (like data poisoning and adversarial examples), so candidates may incorrectly select familiar network or application attacks instead of recognizing the unique AI attack vectors.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data poisoning

Data poisoning (B) is a core AI-specific threat in which an attacker corrupts the training dataset so the model learns incorrect or malicious behavior, degrading accuracy or implanting backdoors. Adversarial examples (C) are also a fundamental AI model threat, where inputs are deliberately perturbed with small, often imperceptible changes that cause the model to misclassify or produce attacker-chosen outputs. By contrast, SQL injection (A) targets database-driven applications through malicious query strings, not the model itself, and DDoS (D) is an availability attack that floods network or service resources rather than manipulating model behavior. Phishing (E) is a social-engineering attack against users' credentials or trust, not a direct threat to AI model integrity or inference.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SQL injection

    Why it's wrong here

    SQL injection exploits database query handling in web applications, not model artefacts, training data or inference endpoints. It is tempting because AI systems often sit behind databases, and it would be the right answer if the question asked about threats to the surrounding application's data layer.

  • ✓

    Data poisoning

    Why this is correct

    Data poisoning corrupts the training set itself, so the model learns manipulated patterns and returns attacker-chosen outputs at inference. It targets the integrity of the learning pipeline rather than the deployed model, making it a recognised threat to AI model security.

  • ✓

    Adversarial examples

    Why this is correct

    Adversarial examples are inputs deliberately perturbed, often imperceptibly, to force misclassification at inference time. They exploit the model's learned decision boundaries rather than its training data, constituting a distinct and common threat to deployed AI model security.

  • ✗

    Distributed denial-of-service (DDoS)

    Why it's wrong here

    DDoS exhausts network or service capacity, degrading availability rather than corrupting, stealing or poisoning a model. It is tempting because inference APIs can be flooded, and it would be correct if the question asked about availability threats to a deployed model-serving endpoint.

  • ✗

    Phishing attacks

    Why it's wrong here

    Phishing targets human credentials and endpoint access, not the model's weights, training pipeline or inference API. It is tempting because phishing is a headline AI-adjacent attack, and it would be correct if the question concerned social engineering against staff who operate or label data for the system.

About these practice questions

One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.